Is a last‑minute lack of clear evidence costing a bid?
Owners and directors often scramble when portals ask for proof of cover.
Portals also ask for GDPR compliance and Cyber Essentials with little notice.
Keep all uploaded files simple and clearly named.
Key evidence to upload for a tender
A tender portal usually accepts a one‑page policy summary.
It usually accepts a broker letter, which is processed faster than a full policy.
Procurement teams read those two documents to confirm limits.
They also check cover lines and insurer contact details.
If the certificate lacks the five required lines, the portal flags the submission for manual review.
That delays the bid.
A clear certificate avoids portal delays and queries.
One‑page certificate template
Keep the certificate to a single page.
Start with the insurer name, policy number and the policy period.
Then list limit per incident, aggregate limit if any, and excess.
Also list the retroactive date and named covers such as ransomware and regulatory fines.
Broker letter exact wording
The broker letter must be on broker‑headed paper.
It should confirm insurer, policy number and limits.
It should state that cover includes ransomware.
It should also include incident response costs, forensic investigation and PR costs.
Add regulatory fines where insurable.
Add a named underwriter contact with telephone and email.
A broker letter on headed paper saves procurement teams significant time by speeding verification.
What file names work best
Use clear file names so assessors find documents quickly.
Example: 01_Policy_Summary.pdf, 02_Broker_Letter.pdf.
Portals often parse file names when screening multiple submissions.
Exact policy lines procurers will check
Procurement assessors look for five explicit cover lines and a clear numeric limit.
They want first‑party business interruption and ransomware or cyber extortion.
They also want incident response cover for forensic, legal and PR costs.
They want third‑party liability for data breaches, and regulatory fines cover where insurable.
If any line is missing or ambiguous, the submission fails validation.
This happens more often than not.
Make sure each cover line is explicit and numeric.
Mandatory clause phrases
Use precise, verifiable phrases.
Example: 'Limit of indemnity: £1,000,000 any one claim'.
Example: 'Cover includes ransomware or cyber extortion and associated forensic costs'.
Common misstatements to avoid
Do not claim 'business insurance covers' unless the insurer explicitly confirms it in writing.
Many standard PL/BI policies exclude perils.
The most frequent error at this point is assuming a non‑cyber policy meets the requirement.
How to show regulatory fines cover
If the insurer covers regulatory fines, show a clause line.
For example, 'cover for regulatory fines and penalties where permitted by law'.
Include any sub‑limits, for example 'sub‑limit £250,000 for regulatory fines'.
Insurance clause examples (paste‑ready)
Insurance: The Supplier shall, at its own cost, maintain the following insurances throughout the Contract term.
The Supplier shall provide a one‑page certificate of insurance and a broker letter on request.
• insurance:
- limit £[X] any one claim
- aggregate £[Y] where required
- excess £[Z]
- retroactive date DD/MM/YYYY
Cover to include ransomware or cyber extortion.
Also include business interruption (first‑party).
Add incident response costs including forensic, legal and PR costs.
Include third‑party liability for data breaches and regulatory fines where insurable.
• Additional insured & waiver: the insurer shall note the Customer as 'additional insured'.
The insurer shall waive rights of subrogation against the Customer where law permits.
• Notification & co‑operation: the Supplier shall notify the insurer within the insurer's contractual notification window.
The Supplier shall co‑operate with the Customer and the insurer in any claims handling.
• Subcontractors: the Supplier shall ensure subcontractors maintain equivalent cover.
Subcontractors shall provide a certificate of insurance evidencing limits and waiver of subrogation.
These clauses are intentionally specific.
The procurement assessor will search for numeric limits, retroactive date, and explicit covers.
They will also search for the waiver and additional insured language to confirm risk transfer.
How cyber essentials and ISO27001 affect cover
Certifications reduce underwriting friction but do not replace policy wording.
Underwriters accept Cyber Essentials as evidence of baseline controls.
This can lower the premium or remove small sub‑limits in many cases.
ISO27001 provides a formal management system and regular audit evidence.
It may lead to broader acceptance of limits for sensitive contracts.
Controls to cite from cyber essentials
Cite MFA and patching when answering PQQs.
Also cite backups with offline copies.
These controls map directly to underwriting questions.
They shorten the insurer's review time.
The Essentials scheme is run via the NCSC and IASME.
It often appears in tender specifications.
What ISO27001 proves to underwriters
ISO27001 provides a risk management system and regular audit evidence.
Tender evaluators see ISO27001 as higher assurance than Essentials for critical systems.
That matters when the buyer asks for higher limits such as NHS contracts.
When certification does not help
Certification does not automatically create cover for regulatory fines, state‑sponsored attacks, or prior acts.
That is true in theory.
In practice, an insurer will still check retroactive dates and prior‑act exclusions before confirming cover.
Step‑by‑step: align Essentials / ISO27001 with policy and tender documentation
1) Review the PQQ and contract.
Extract numeric limits, named wording and the retroactive date.
Also note any named insurer requirements.
2) Map controls.
Take Cyber Essentials and ISO27001 artefacts.
Map specific controls such as MFA, patching cadence and backups to underwriting questions.
Add the incident response plan to the same matrix.
3) Engage the broker.
Ask for a one‑page policy summary and an insurer confirmation letter.
Ask the broker to cite the mapped controls and to confirm cover lines.
4) Build the evidence pack.
Include the certificate of insurance and the broker letter.
Also include the Cyber Essentials summary or the ISO27001 scope and certificate.
Add short PQQ snippets that reference the broker letter lines.
5) Verify retroactive dates and prior‑act exclusions.
Confirm these with the insurer.
Document them in the policy summary.
6) Upload in this order: policy summary, broker letter, certification and PQQ snippets.
Keep the underwriter contact for procurement assessors.
This avoids manual review delays.
This sequence reduces friction between security certification and insurer wording.
It ensures each control is evidenced and tied to the insurer's statements on the policy summary or broker letter.
Comparative matrix to pick the right policy
Choose a policy based on measurable items.
Include limit per incident, aggregate limit, ransomware cover, incident response cost limit, retroactive date, excess and the insurer's notification window.
A matrix with these criteria helps procurers and bid teams match contract requirements quickly.
Use the table below to decide without reading full wordings.
A short matrix greatly speeds procurement and validation checks.
| Policy |
Limit per incident |
Aggregate limit |
Ransomware cover |
IR costs limit |
Retroactive date |
Excess |
| Policy A |
£1,000,000 |
£2,000,000 |
Yes |
£150,000 |
01/01/2020 |
£5,000 |
| Policy B |
£5,000,000 |
No |
Yes |
£500,000 |
01/01/2018 |
£10,000 |
Suggested thresholds to meet tenders
Aim for a limit per incident of at least £1,000,000 for most public sector tenders.
For health or critical infrastructure, aim for £5,000,000 where requested.
Check the PQQ; the buyer sets the final threshold.
Simple decision rules
Pick the lowest cost policy that meets the tender's numeric limits.
Also ensure the policy has clear ransomware and incident response cover.
If the contract needs aggregate protection, choose a policy with an aggregate equal or higher than the contract value.
Tender upload flow
1. One‑page policy summary
2. Broker letter with insurer contact
3. Certification proof (Cyber Essentials/ISO)
4. Short PQQ snippets mapped to clauses
Sector examples: NHS, defence and critical infrastructure (illustrative)
NHS tenders: Typical NHS frameworks require at least a £5,000,000 limit per incident.
They require explicit ransomware cover.
They also need an incident response costs sub‑limit sufficient to fund immediate forensic and PR activity.
This is often £250k–£500k.
Buyers expect a retroactive date that covers any prior acts during the service delivery period.
NHS evaluators will check the certificate of insurance for 'cover includes ransomware/extortion' and an underwriter contact.
Also ensure evidence of the Data Security & Protection Toolkit or equivalent is included.
Include this alongside Cyber Essentials or ISO27001.
Defence: MOD or defence‑adjacent procurements may require a named insurer or NCSC/NATO‑grade wording.
Exclusions for state‑sponsored acts must be addressed explicitly.
Buyers may ask for proof of insurer appetite for sensitive work.
Expect requests for full policy wordings and the underwriter's written consent.
Simple certificates are often insufficient.
Critical infrastructure: For utilities or transport, procurers commonly require higher limits.
They often want long retroactive dates and tight notification windows.
Show a policy summary with 'limit per incident', 'aggregate' and 'retroactive date'.
Add an explicit statement on business interruption cover tied to cyber events.
Procurement assessors use those five lines to fast‑track validation in these sectors.
Subcontractor insurability pitfalls
Hiring a subcontractor without checking their wording causes most post‑award insurance disputes.
The usual failings are missing waiver of subrogation, no 'additional insured' wording, and lower limits than the prime contract.
These gaps commonly cause disqualification at evaluation or liability shortfalls after an incident.
Always check subcontractor certificates promptly before contract award.
Checklist for subcontractor proof
Ask for a one‑page policy summary, broker letter and a copy of the subcontractor's certificate of currency.
Confirm their limit equals or exceeds the contract requirement and ask for an insurer waiver if the contract demands it.
Failures seen in practice
One case: a supplier uploaded a PL certificate, but the insurer had excluded perils.
The prime lost time negotiating after award and the buyer questioned compliance.
This error increases delivery risk and may affect payment schedules.
How to manage subcontractor premiums
Document any premium uplift in the commercial schedule and show an amortised cost per contract year.
Present insurers' confirmation that subcontractors' cover meets the prime contract requirement.
Paste‑ready PQQ answers and policy excerpts
Provide three levels of response for each common PQQ question: short, expanded and policy‑mapped.
The short answer fits a single field.
The expanded response provides two sentences.
The policy‑mapped response cites the broker letter line or certificate clause.
Short and expanded snippets
Short: 'We hold insurance with [Insurer], policy [number], limit £1,000,000 any one claim.'
Expanded: 'We hold cover with [Insurer], policy [number]. Cover includes ransomware, incident response, forensic costs and third‑party liability, limit £1,000,000 any one claim.'
Policy mapping examples
Map each sentence to a clause.
Example mapping: 'limit £1,000,000 any one claim' → certificate line 'Limit of indemnity'.
'ransomware' → broker letter phrase 'includes ransomware and extortion'.
Insurer: [Name] Policy number:
- [12345] Limit: £1,000,000 any one claim Aggregate: £2,000,000 (if applicable) Excess: £5,000 Retroactive date: DD/MM/YYYY Cover includes: ransomware/cyber extortion
- incident response costs (forensic, legal, PR)
- third‑party liability
- regulatory fines where insurable
Underwriter contact: [name, email, phone]
Why full policies slow validation and how to avoid it
Many bids fail initial validation because assessors cannot quickly find the five required lines in long policies.
Portals and procurement officers prefer short, verifiable extracts and a broker letter.
Uploading the full policy first often triggers manual review.
Preferred file set for portals
Upload a one‑page policy summary and a signed broker letter first.
Include Cyber Essentials or ISO27001 certificates as separate files.
Provide the full wording only if requested.
What triggers manual review
Omissions such as no retroactive date, ambiguous ransomware wording, lack of underwriter contact, or prior acts exclusions trigger queries.
Procurement teams often ask for clarification when these appear.
Example portal behaviour
Central buying organisations often expect certification and insurer confirmation as separate files.
For example, the Crown Commercial Service requests clear insurer contact details and signed declarations in many frameworks.
Pricing: how to include insurance costs in a bid
Show insurance costs transparently as a commercial line item.
Break down annual premium, excess retained, and the amortised contract cost.
Buyers expect the supplier to show that the premium reflects the required risk transfer.
Template pricing line item
insurance: annual premium £1,200; excess retained £5,000.
Amortised two‑year cost charged to this contract: £2,400.
Justification: cost reflects required cover limits and ransomware cover requested by buyer.
How to defend a premium uplift
Link premium to tender requirements and insurer confirmation.
If higher limits or specific wording increase the premium, attach insurer evidence.
Also attach the broker letter mapping the extra cost to the extra cover.
If the bid deadline is tight, request a broker's one‑page insurer confirmation and underwriter contact to upload with the tender.
That shortens validation time.
This guidance does not apply when the tender specifies mandatory wording or a named insurer. It also does not apply when the buyer requires NCSC, NATO or defence grade wording. It does not apply when previous incidents have created exclusions that make standard cyber cover unavailable. In those situations the buyer's conditions take precedence. A broker should obtain a bespoke wording or insurer consent as required.
Frequently asked questions
Do i need cyber insurance to bid on UK government
Yes.
Many government tenders require proof of insurance for contracts that manage personal data or critical systems.
Typical minimums are £1,000,000 per incident.
Some sensitive contracts ask for £5,000,000.
Always check the PQQ.
How do i prove cyber security compliance in a tender
Provide Cyber Essentials or ISO27001 certification with expiry dates.
Also include a one‑page policy summary and a broker letter.
Map two technical controls such as MFA and backup to your insurer's underwriting answers to speed validation.
Is cyber essentials enough for government tenders?
Cyber Essentials is often accepted for lower‑risk contracts.
It is not always sufficient for health or critical services.
Use ISO27001 when the PQQ requests higher assurance or when the buyer names ISO specifically.
What cyber insurance evidence is required for NHS
NHS tenders commonly request at least a £5,000,000 limit per incident.
They also need explicit ransomware and incident response cover.
Buyers check for a retroactive date without prior‑acts gaps.
Check the specific contract notice for thresholds.
What wording should be used in tender
Use verifiable phrases:
- 'Insurer: [name]'
- 'Policy number: [number]'
- 'Limit: £[X] any one claim'
- 'Aggregate: £[Y]'
- 'Excess: £[Z]'
- 'Retroactive date: DD/MM/YYYY'
- 'Coverage includes ransomware/cyber extortion, incident response (forensic/legal/PR), third‑party liability and regulatory fines where insurable.'
How long does it take to get a broker letter and underwriter confirmation
A broker can usually issue a one‑page certificate within 24 to 72 hours.
This assumes the account is active and there are no prior incidents.
Allow up to 7 days when underwriting review is needed or for new policies.
What to do now
Gather these items in this order.
Include a one‑page policy summary and a signed broker letter with underwriter contact.
Also include Cyber Essentials or an ISO27001 certificate and short PQQ snippets mapped to clauses.
Then upload certificates to the portal in the file order shown earlier.
Keep underwriter contact details handy for validation calls.
The evidence checklist below is copy‑ready and works for most PQQs.
Use it to avoid the most common errors.
Common errors are missing retroactive date, ambiguous ransomware wording, and absent underwriter contact.
- One‑page policy summary with numeric limits
- Signed broker letter confirming insurer and covers
- Cyber Essentials or ISO27001 certificate with expiry date
- Short PQQ snippets (short, expanded, policy‑mapped)
- Subcontractor one‑page certificates where applicable
ICO guidance on reporting a personal data breach